What k3s-io/k3s shipped
Written by FoxPlug from public releases; not affiliated with K3s. An automatic summary of the public release, pull request and commit data of github.com/k3s-io/k3s. K3s did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Released v1.37.1-rc2+k3s1 with security fixes for anonymous access to supervisor router and improved CA hash validation. Release
- Released v1.36.5-rc2+k3s1 with security fixes for anonymous access to supervisor router and improved CA hash validation. Release
- Released v1.35.9-rc2+k3s1 with security fixes for anonymous access to supervisor router and improved CA hash validation. Release
- Released v1.34.12-rc2+k3s1 with security fixes for anonymous access to supervisor router and improved CA hash validation. Release
- Fixed agent CA bundle validation to only trust root CAs with matching hash when join token includes CA hash instead of trusting all certs in the bundle. Pull request #14699
- Bumped cadvisor to v0.60.5-k3s1 to improve access to the argContainerdRuntime variable in cadvisor lib/containerd. Pull request #14697
- Bumped helm-controller for Harvester webhook workarounds fixing ConfigMap creation issues during cluster upgrade or cold start. Pull request #14684
- Fixed issue where unsynced cache would cause multiple node password secret create attempts during startup with spurious errors. Pull request #14675
Why it matters
Security fixes for anonymous access control and CA validation are released across four supported release branches. The CA bundle validation fix addresses a CVE affecting how agents trust certificates during cluster join. Supporting component updates improve stability during cluster operations.
Changelog entry
- Reject anonymous access to supervisor router endpoints for spegel, pprof, and metrics Pull request #14701
- Improve CA hash validation for agent certificate trust Pull request #14705
- Bump cadvisor to v0.60.5-k3s1 Pull request #14697
- Bump helm-controller with Harvester webhook fixes Pull request #14684
- Require node password informer sync before using cache to prevent spurious errors during startup Pull request #14675
K3s v1.37.1-rc2, v1.36.5-rc2, v1.35.9-rc2, and v1.34.12-rc2 are now available with security fixes for supervisor router access and CA hash validation improvements.
K3s has released candidate versions across four release branches (v1.37.1-rc2, v1.36.5-rc2, v1.35.9-rc2, v1.34.12-rc2) with important security updates. These releases fix anonymous access to supervisor endpoints and improve CA hash validation during agent join. Additional improvements address ConfigMap creation during cluster upgrades and node password management.
Week of September 14, 2026
What shipped
- Kubernetes v1.37.0 is now available in K3s as v1.37.0+k3s1. Release
- KMS providers are now excluded from apiserver readiness checks, allowing kubelet to start before KMS providers are available. Pull request #14635
- K3s now waits up to 60 seconds for a default network route to appear during startup instead of failing immediately. Pull request #14527
- Release 1.37 branch received backports including network route detection and KMS provider fixes. Pull request #14631
- Release 1.36 branch received backports for etcd store fix and network improvements. Pull request #14632
- Release 1.35 branch received backports for etcd store fix and network improvements. Pull request #14633
- Release 1.34 branch received backports for etcd store fix and network improvements. Pull request #14634
Why it matters
K3s v1.37.0 ships with Kubernetes 1.37.0 and fixes startup reliability issues when network routes or KMS providers are not immediately available. These fixes are backported across multiple release branches to address real-world deployment scenarios.
Changelog entry
- Kubernetes updated to v1.37.0 Release
- KMS providers excluded from apiserver readiness check to allow kubelet startup before KMS providers are available Pull request #14635
- Added 60-second wait for default network route during host interface detection to prevent startup failures Pull request #14527
[6] K3s v1.37.0+k3s1 is available, updating Kubernetes to v1.37.0 with fixes for network route detection and KMS provider startup handling.
[6] K3s v1.37.0+k3s1 is now available with Kubernetes v1.37.0. This release improves startup reliability with fixes for network route detection [1] and KMS provider initialization [0], ensuring K3s clusters can start reliably in varied network environments.